Design a multi-domain or multi-forest Active Directory environment
Advanced
Administrator
Identity and Access Administrator
Windows Server
Learn how to extend a single-domain AD DS deployment when you need multiple domains or forests, complex delegation, trusts, advanced replication, or read-only domain controllers.
Learning objectives
In this module, you'll:
- Determine when security isolation, legal separation, administrative autonomy, mergers, or replication constraints justify multiple domains or forests.
- Design forest roots, domain trees, directory and application partitions, namespace coexistence, and global catalog scope.
- Design OU structure, delegation, GPO scope and inheritance, protected objects, and schema governance.
- Design trust direction, transitivity, selective authentication, SID filtering, SIDHistory governance, and cross-forest name resolution.
- Plan universal group membership, global catalog placement, and authentication paths across domains and forests.
- Analyze advanced replication risks and plan domain controller capacity and failure domains.
- Design RODC branch deployments, including Password Replication Policy and delegated administration.
Prerequisites
- Experience administering AD DS, including domain controller promotion, DNS, Group Policy, and PowerShell.
- Familiarity with single-domain forest design, sites, and replication topology.